Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
BID:70411
Info
Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
| Bugtraq ID: | 70411 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2014 12:00AM |
| Updated: | Oct 13 2014 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
Croogo is prone to multiple arbitrary PHP code-execution vulnerabilities because it fails to properly verify the uploaded files.
An attacker can exploit these issues to execute arbitrary PHP code within the context of the web server.
Croogo 2.0.0 is vulnerable; other versions may also be affected.
Croogo is prone to multiple arbitrary PHP code-execution vulnerabilities because it fails to properly verify the uploaded files.
An attacker can exploit these issues to execute arbitrary PHP code within the context of the web server.
Croogo 2.0.0 is vulnerable; other versions may also be affected.
Exploit / POC
Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
An attacker can exploit these issues using a web browser.
The following exploit code is available:
An attacker can exploit these issues using a web browser.
The following exploit code is available:
Solution / Fix
Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Croogo Multiple Arbitrary PHP Code Execution Vulnerabilities
References:
References:
- Croogo CMS homepage (Croogo)